TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Air France-KLM estimated > 500M travel data vulnerable via 6-char code

7 点作者 bwblabs超过 1 年前

1 comment

bwblabs超过 1 年前
Researcher of the leak. I got a question from NOS to test the security of a 6-length short code link (<a href="https:&#x2F;&#x2F;www.klm.nl&#x2F;s&#x2F;xxxxxx" rel="nofollow noreferrer">https:&#x2F;&#x2F;www.klm.nl&#x2F;s&#x2F;xxxxxx</a>) used in text messages. I&#x27;ve tested two ranges (FAbxxx and KLmxxx), which gave a consistent 1% hit ratio of customer data (57% Air France, 43% KLM), NOS tested a smaller size random set (and got about 0.5%), 62^6*0.01=568 million. It was probably base64url (we now know - was also used, not yet got a _ confirmation).<p>Original posting of Dutch article: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38681302">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=38681302</a>